US8908691B2

Virtual ethernet port aggregation (VEPA)-enabled multi-tenant overlay network

Summary by NHIP

VEPA-enabled multi-tenant overlay network

The system enables Virtual Ethernet Port Aggregation in an overlay network by routing packets between virtual machines through a physical networking element for inspection. A virtual switch encapsulates Layer-3 packets with tunnel headers containing virtual network identifiers before sending them via a Layer-3 tunnel to the physical element.

Claim Score by NHIP

Read claim 18, the broadest

Abstract

In accordance with one embodiment, a system that may be used for enabling Virtual Ethernet Port Aggregation (VEPA) in an overlay network includes a host server providing a virtual switch, the virtual switch including logic adapted for receiving a packet from a first virtual machine (VM) on the host server, logic adapted for determining that a destination of the packet is a second VM common to the host server, logic adapted for encapsulating the packet with a tunnel header to form an overlay packet, logic adapted for sending the overlay packet via a tunnel to a physical networking element to have inspection services performed thereon, logic adapted for receiving the overlay packet from the physical networking element, logic adapted for de-encapsulating the overlay packet to retrieve a serviced packet, and logic adapted for forwarding the serviced packet to the second VM, wherein the tunnel header includes tenant specific information.

US8908691B2, drawing sheet 1
Sheet 1 of 9

Term

6 yearsleft in the term

Expires 6 September 2032, including 93 days of term adjustment.

  1. Priority and filed
  2. Granted
  3. Today
  4. Expires

20 claims: 4 independent, 16 dependent

  1. 1
    A system, comprising:a host server providing a virtual switch, the virtual switch comprising: logic configured to receive a packet from a first virtual machine (VM) on the host server;logic configured to determine that a destination of the packet is a second VM common to the host server;logic configured to encapsulate the packet with a Layer-3 tunnel header to form an overlay packet, the overlay packet being configured as a Layer-3 packet;logic configured to send the overlay packet via a Layer-3 tunnel to a physical networking element to have inspection services performed thereon;logic configured to receive the overlay packet via the Layer-3 tunnel from the physical networking element after services have been performed thereon;logic configured to de-encapsulate the overlay packet to retrieve a serviced packet;and logic configured to forward the serviced packet to the second VM, wherein the tunnel header comprises tenant specific information, the tenant specific information including a virtual network identifier (VNID), and wherein the host server is configured to natively transport Layer-3 packets across the Layer-3 tunnel.
  2. 7
    A method for enabling Virtual Ethernet Port Aggregation (VEPA) in an overlay network, the method comprising:receiving a packet from a first virtual machine (VM) on a host server;determining that a destination of the packet is a second VM common to the host server;encapsulating the packet with a Layer-3 tunnel header to form an overlay packet, the overlay packet being configured as a Layer-3 packet;sending the overlay packet via a Layer-3 tunnel to a physical networking element to have inspection services performed thereon;receiving the overlay packet via the Layer-3 tunnel from the physical networking element after services have been performed thereon;de-encapsulating the overlay packet to retrieve a serviced packet;and forwarding the serviced packet to the second VM, wherein the tunnel header comprises tenant specific information, the tenant specific information including a virtual network identifier (VNID), and wherein the overlay packet is natively transported as a Layer-3 packet across the Layer-3 tunnel.
  3. 13
    A computer program product for enabling Virtual Ethernet Port Aggregation (VEPA) in an overlay network, the computer program product comprising a computer readable storage medium having computer readable program code embodied therewith, the computer readable program code comprising:computer readable program code configured to receive a packet from a first virtual machine (VM) on a host server;computer readable program code configured to determine that a destination of the packet is a second VM common to the host server;computer readable program code configured to encapsulate the packet with a Layer-3 tunnel header to form an overlay packet, the overlay packet being configured as a Layer-3 packet;computer readable program code configured to send the overlay packet via a Layer-3 tunnel to a physical networking element to have inspection services performed thereon;computer readable program code configured to receive the overlay packet via the Layer-3 tunnel from the physical networking element after services have been performed thereon;computer readable program code configured to de-encapsulate the overlay packet to retrieve a serviced packet;and computer readable program code configured to forward the serviced packet to the second VM, wherein the tunnel header comprises tenant specific information, the tenant specific information including a virtual network identifier (VNID), and wherein the host server is configured to natively transport Layer-3 packets across the Layer-3 tunnel.
  4. 18
    Broadest claimClaim Score 54, average(NHIP)A system, comprising:logic configured to receive an overlay packet from a virtual switch via a Layer-3 overlay tunnel;logic configured to de-encapsulate the overlay packet by removing a Layer-3 overlay tunnel header to retrieve an inner packet;logic configured to determine a source and destination of the inner packet;logic configured to perform inspection services on the inner packet based on tenant specific information included in the overlay packet;logic configured to determine whether to send the inner packet to the destination;logic configured to, when the determination is to send the inner packet to the destination, re-encapsulate the inner packet into the Layer-3 overlay tunnel header to form the overlay packet and send the overlay packet to the virtual switch via the Layer-3 overlay tunnel;and logic configured to, when the determination is to not send the packet to the destination, drop the packet, wherein the overlay tunnel header comprises tenant specific information, the tenant specific information including a virtual network identifier (VNID), and wherein the system is configured to natively transport Layer-3 overlay packets across the Layer-3 overlay tunnel.